~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
PublicDateAtUSN: 2009-10-23
Candidate: CVE-2009-3767
PublicDate: 2009-10-23
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3767
 http://www.ubuntu.com/usn/usn-858-1
Description:
 libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other
 versions, when OpenSSL is used, does not properly handle a '\0' character
 in a domain name in the subject's Common Name (CN) field of an X.509
 certificate, which allows man-in-the-middle attackers to spoof arbitrary
 SSL servers via a crafted certificate issued by a legitimate Certification
 Authority, a related issue to CVE-2009-2408.
Ubuntu-Description:
Notes:
 mdeslaur> openldap in hardy and intrepid only have gnutls backend
 mdeslaur> we compile jaunty-lucid with gnutls, not openssl
 mdeslaur> so we're not vulnerable to this. (debian/configure.options)
 mdeslaur>
 mdeslaur> openldap2 in dapper has been patched with gnutls support, so
 mdeslaur> not vulnerable. This is the library to which all dapper
 mdeslaur> applications are linked, to not conflict with the openssl
 mdeslaur> license.
 mdeslaur>
 mdeslaur> openldap2.2 in dapper uses openssl and is vulnerable.
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=553432
 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2009-3767
Priority: medium
Discovered-by:
Assigned-to:

Patches_openldap:
 upstream: http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.8&r2=1.11&f=h
 upstream: http://www.openldap.org/devel/cvsweb.cgi/libraries/libldap/tls_o.c.diff?r1=1.11&r2=1.12&hideattic=1&sortbydate=0 (related?)
upstream_openldap: needs-triage
dapper_openldap: DNE
hardy_openldap: DNE
intrepid_openldap: not-affected (code not present)
jaunty_openldap: not-affected (not compiled with openssl)
karmic_openldap: not-affected (not compiled with openssl)
devel_openldap: not-affected (not compiled with openssl)

Patches_openldap2.3:
upstream_openldap2.3: needs-triage
dapper_openldap2.3: DNE
hardy_openldap2.3: not-affected (code not present)
intrepid_openldap2.3: DNE
jaunty_openldap2.3: DNE
karmic_openldap2.3: DNE
devel_openldap2.3: DNE

Patches_openldap2.2:
upstream_openldap2.2: needs-triage
dapper_openldap2.2: released (2.2.26-5ubuntu2.9)
hardy_openldap2.2: DNE
intrepid_openldap2.2: DNE
jaunty_openldap2.2: DNE
karmic_openldap2.2: DNE
devel_openldap2.2: DNE

Patches_openldap2:
upstream_openldap2: needs-triage
dapper_openldap2: not-affected (compiled with gnutls patch)
hardy_openldap2: DNE
intrepid_openldap2: DNE
jaunty_openldap2: DNE
karmic_openldap2: DNE
devel_openldap2: DNE